← Back

CVE-2009-2975

nvd nist
Published: Aug 27, 2009Modified: Apr 23, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

Mozilla Firefox 3.5.2 on Windows XP, in some situations possibly involving an incompletely configured protocol handler, does not properly implement setting the document.location property to a value specifying a protocol associated with an external application, which allows remote attackers to cause a denial of service (memory consumption) via vectors involving a series of function calls that set this property, as demonstrated by (1) the chromehtml: protocol and (2) the aim: protocol.

Affected (1)

Products: Mozilla: Firefox
1 product
Firefox
Configuration A
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Version 3.5.2
Running on/withPlatform Versions
Microsoft
Windows Xp
All versions

Timeline

No history available yet.